To keep its cache database efficient, `named` running as a recursive resolver occasionally attempts to clean up the database. It uses several methods, including some that are asynchronous: a small chunk of memory pointing to the cache element that can be cleaned up is first allocated and then queued for later processing. It was discovered that if the resolver is continuously processing query patterns triggering this type of cache-database maintenance, `named` may not be able to handle the cleanup events in a timely manner. This in turn enables the list of queued cleanup events to grow infinitely large over time, allowing the configured `max-cache-size` limit to be significantly exceeded. This issue affects BIND 9 versions 9.16.0 through 9.16.45 and 9.16.8-S1 through 9.16.45-S1.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade bind-utilsUpgrade bind-libsUpgrade bind9.16-utilsUpgrade bind-dnssec-docUpgrade python3-bind9.16Upgrade bind-develUpgrade bind-chrootUpgrade bind9.16Upgrade bind9.16-develUpgrade python3-bindUpgrade bind9.16-docUpgrade bind-dnssec-utilsUpgrade bind9.16-chrootUpgrade bind9.16-licenseUpgrade bind-licenseUpgrade bind-dyndb-ldapUpgrade bind-docUpgrade bindUpgrade bind9.16-dnssec-utilsUpgrade bind9.16-libs | Apr 15, 2024 | Feb 13, 2024 |
| Alpine Linux | — | Upgrade bind | Mar 26, 2024 | Feb 13, 2024 |
| Amazon_linux_2023 | — | Upgrade bind-debugsourceUpgrade bind-pkcs11-libs-debuginfoUpgrade bind-docUpgrade bind-pkcs11Upgrade bindUpgrade bind-pkcs11-debuginfoUpgrade bind-chrootUpgrade bind-pkcs11-utils-debuginfoUpgrade bind-dlz-sqlite3Upgrade bind-debuginfoUpgrade bind-dlz-filesystem-debuginfoUpgrade bind-pkcs11-libsUpgrade bind-utilsUpgrade bind-libsUpgrade bind-utils-debuginfoUpgrade bind-pkcs11-utilsUpgrade bind-dnssec-docUpgrade bind-dlz-filesystemUpgrade python3-bindUpgrade bind-libs-debuginfoUpgrade bind-dlz-ldapUpgrade bind-dnssec-utils-debuginfoUpgrade bind-dlz-mysql-debuginfoUpgrade bind-dlz-sqlite3-debuginfoUpgrade bind-pkcs11-develUpgrade bind-dlz-ldap-debuginfoUpgrade bind-dnssec-utilsUpgrade bind-dlz-mysqlUpgrade bind-develUpgrade bind-license | Feb 17, 2025 | Feb 13, 2024 |
| Debian | — | Upgrade bind9 | Jul 30, 2024 | Feb 13, 2024 |
| Dell Powerstore Dsa2024462 | — | Upgrade Dell PowerStoreOS to the latest version | Oct 23, 2025 | Nov 20, 2024 |
| Dell Powerstore Dsa2024497 | — | Upgrade Dell PowerStoreOS to the latest version | Oct 23, 2025 | Dec 19, 2024 |
| Dell Powerstore Dsa2025050 | — | Upgrade Dell PowerStoreOS to the latest version | Oct 23, 2025 | Jan 28, 2025 |
| Dns Bind | — | Upgrade ISC BIND to latest version | Feb 15, 2024 | Feb 15, 2024 |
| Huawei Euleros 2_0_sp11 | — | Upgrade bind-licenseUpgrade bind-pkcs11-utilsUpgrade bindUpgrade bind-dnssec-utilsUpgrade bind-pkcs11Upgrade bind-utilsUpgrade bind-dnssec-docUpgrade bind-chrootUpgrade bind-pkcs11-libsUpgrade bind-libsUpgrade python3-bind | Jun 3, 2024 | Feb 13, 2024 |
| Huawei Euleros 2_0_sp12 | — | Upgrade bind-chrootUpgrade bind-dnssec-docUpgrade bind-pkcs11-libsUpgrade bind-utilsUpgrade python3-bindUpgrade bind-dnssec-utilsUpgrade bind-pkcs11-utilsUpgrade bind-licenseUpgrade bind-pkcs11Upgrade bindUpgrade bind-libs | May 31, 2024 | Feb 13, 2024 |
| Ibm Aix | — | Apply the fix or workaround for bind_advisory26 | Jun 5, 2024 | Feb 13, 2024 |
| Oracle_linux | — | Upgrade bind9.16-chrootUpgrade bind9.16-dnssec-utilsUpgrade bind-licenseUpgrade bind-develUpgrade python3-bindUpgrade bind9.16-utilsUpgrade bind9.16Upgrade bind9.16-licenseUpgrade bindUpgrade python3-bind9.16Upgrade bind-libsUpgrade bind-dyndb-ldapUpgrade bind9.16-develUpgrade bind-docUpgrade bind9.16-docUpgrade bind-dnssec-docUpgrade bind-chrootUpgrade bind9.16-libsUpgrade bind-dnssec-utilsUpgrade bind-utils | Apr 12, 2024 | Feb 13, 2024 |
| Redhat_linux | — | Upgrade bind-docUpgrade bind9.16-libsUpgrade bind-utils-debuginfoUpgrade bind9.16-docUpgrade bind-debugsourceUpgrade bind-utilsUpgrade bind-chrootUpgrade bind-dnssec-docUpgrade bind-dnssec-utilsUpgrade bind9.16-develUpgrade bind-dyndb-ldap-debuginfoUpgrade bind-licenseUpgrade bind-libsUpgrade bind-develUpgrade bind9.16-dnssec-utils-debuginfoUpgrade python3-bindUpgrade bindUpgrade bind9.16Upgrade bind9.16-libs-debuginfoUpgrade bind9.16-utils-debuginfoUpgrade bind9.16-debugsourceUpgrade bind-dyndb-ldap-debugsourceUpgrade bind-debuginfoUpgrade bind9.16-chrootUpgrade bind9.16-dnssec-utilsUpgrade bind-dyndb-ldapUpgrade python3-bind9.16Upgrade bind9.16-licenseUpgrade bind-libs-debuginfoUpgrade bind-dnssec-utils-debuginfoUpgrade bind9.16-utilsUpgrade bind9.16-debuginfo | Apr 3, 2024 | Feb 13, 2024 |
| Rocky_linux | — | Upgrade bind-utils-debuginfoUpgrade bind-dyndb-ldap-debuginfoUpgrade bind9.16-debuginfoUpgrade bind-libs-debuginfoUpgrade bind9.16-utilsUpgrade bind-dyndb-ldapUpgrade bind9.16-debugsourceUpgrade bind9.16-chrootUpgrade bind-dnssec-utils-debuginfoUpgrade bind-libsUpgrade bind9.16-dnssec-utilsUpgrade bind-dyndb-ldap-debugsourceUpgrade bind9.16-dnssec-utils-debuginfoUpgrade bind9.16-utils-debuginfoUpgrade bind9.16Upgrade bind9.16-libs-debuginfoUpgrade bind9.16-libsUpgrade bind-chrootUpgrade bind9.16-develUpgrade bind-debuginfoUpgrade bind-utilsUpgrade bindUpgrade bind-dnssec-utilsUpgrade bind-debugsourceUpgrade bind-devel | May 8, 2024 | Feb 13, 2024 |
| Suse | — | Upgrade bindUpgrade bind-utilsUpgrade bind-docUpgrade libirs-develUpgrade bind-develUpgrade bind-chrootenvUpgrade python3-bindUpgrade libbind9-1600Upgrade libns1604Upgrade libuv-develUpgrade libuv1Upgrade libdns1605Upgrade libisccfg1600Upgrade libisc1606Upgrade libirs1601Upgrade libisccc1600 | Feb 22, 2024 | Feb 13, 2024 |
| Ubuntu | — | Upgrade bind9 | Feb 21, 2024 | Feb 13, 2024 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Feb 13, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub